Releases
v2.153.0
Compare
Sorry, something went wrong.
No results found
Features
add actor_via_sso to audit log (#1002 ) (c52de4a )
add GOTRUE_<PROVIDER>_SKIP_NONCE_CHECK to skip nonce checks in ODIC flow (#1264 ) (4291959 )
add is_sso_user column to users which allows duplicate emails to exist on those rows (#828 ) (0e2cd70 )
add kid, iss, iat claims to the JWT (#1148 ) (3446197 )
add provider claim to amr when the method is sso/saml (#837 ) (68acb95 )
add array attribute mapping for SAML (#1526 ) (7326285 )
add cleanup for session timebox and inactivity timeout (#1298 ) (9226979 )
add cleanup of unverified factors in 24 hour window (#1379 ) (0100a80 )
add configuration for custom sms sender hook (#1428 ) (1ea56b6 )
add CORS allowed headers config (#1197 ) (7134000 )
add custom access token hook (#1332 ) (312f871 )
add custom sms hook (#1474 ) (0f6b29a )
add database cleanup logic, runs after each request (#875 ) (aaad5bd )
add different logout scopes (#1112 ) (df07540 )
add email rate limit breach metric (#1208 ) (4ff1fe0 )
add endpoint to resend email confirmation (#912 ) (a50b5a7 )
add endpoint to unlink identity from user (#1315 ) (af83b34 )
add error codes (#1377 ) (e4beea1 )
add Figma provider (#1139 ) (007324c )
add fly oauth provider (#1261 ) (0fe4285 )
add friendly name to enroll factor response (#1277 ) (3c72faf )
add generated admin client (#924 ) (3ee3f34 )
add haveibeenpwned.org password strength check (#1324 ) (c3acfe7 )
add idempotent refresh token algorithm (#1278 ) (b0426c6 )
add idle db connection options (duration, count, healthcheck period) (#811 ) (e187280 )
add inactivity-timeout to sessions (#1288 ) (6c8a96e )
add index on user_id of mfa_factors (#1247 ) (6ea135a )
add kakao OIDC (#1381 ) (b5566e7 )
add log entries for pkce (#1068 ) (9c3ba87 )
add manual linking APIs (#1317 ) (80172a1 )
add mfa cleanup (#1105 ) (f5c9afb )
add mfa indexes (#746 ) (cb6a879 )
add MFA support (disabled by default) (#736 ) (940f582 )
add mfa verification postgres hook (#1314 ) (db344d5 )
Add new Kakao Provider (#834 ) (bafb89b )
add new Linkedin OIDC due to deprecated scopes for new linkedin applications (#1248 ) (f40acfe )
add opentelemetry tracer and metrics (#679 ) (650fa3b )
add password hashing metrics (#769 ) (47adfef )
add PKCE (OAuth) (#891 ) (cf47ec2 )
add pkce recovery (#1022 ) (1954560 )
add pkce to email_change routes (#1082 ) (0f8548f )
add required characters password strength check (#1323 ) (3991bdb )
add safe deferred closing (#945 ) (29c431f )
add SAML config (disabled by default) (#759 ) (91fa9bd )
add saml metadata force update every 24 hours (#1020 ) (965feb9 )
add send email Hook (#1512 ) (cf42e02 )
add session id to required claim for output of custom access token hook (#1360 ) (31222d5 )
add single session per user with tags support (#1297 ) (69feebc )
add soft delete option to admin delete endpoint (#489 ) (2a2f425 )
add sso pkce (#1137 ) (2c0e0a1 )
add support for Azure CIAM login (#1541 ) (1cb4f96 )
add support for Twilio Verify (#1124 ) (7e240f8 )
add test OTP support for mobile app reviews (#1166 ) (2fb0cf5 )
add time-boxed sessions (#1286 ) (9a1f461 )
add timeout middleware (#1529 ) (f96ff31 )
add turnstile support (#1094 ) (b1d2f1c )
add weak password check on sign in (#1346 ) (8785527 )
allow POST /verify to accept a token hash (#1165 ) (e9ab555 )
allow whatsapp channels with Twilio Verify (#1207 ) (ff98d2f )
allow for postgres and http functions on each extensibility point (#1528 ) (348a1da )
allow more than one verified factor per user (#856 ) (47e4afc )
allow unverified email signins (#1301 ) (94293b7 )
allow updating saml providers metadata_xml (#1096 ) (20e503e )
alter tag to use raw (#1427 ) (53cfe5d )
anonymous sign-ins (#1460 ) (130df16 )
azure oidc fix (#1349 ) (97b3595 )
calculate aal without transaction (#1437 ) (8dae661 )
clean up expired factors (#1371 ) (5c94207 )
clean up test setup in MFA tests (#1452 ) (7185af8 )
complete OIDC support for Apple and Google providers (#1108 ) (aab7c34 )
configurable NameID format for SAML provider (#1481 ) (ef405d8 )
deprecate and explicitly allow freeform ID token issuers (#934 ) (99df661 )
deprecate existing webhook implementation (#1417 ) (5301e48 )
drop restriction that PKCE cannot be used with autoconfirm (#1176 ) (0a6f218 )
drop SAML RelayState IP address check (#1376 ) (6284d99 )
drop sha hash tag (#1422 ) (76853ce )
expose email address being sent to for email change flow (#1231 ) (f7308ad )
fix account linking (#1098 ) (93d12d9 )
fix empty string parsing for GOTRUE_SMS_TEST_OTP_VALID_UNTIL (#1234 ) (25f2dcb )
fix refresh token reuse revocation (#1312 ) (6e313f8 )
fix SAML metadata XML update on fetched metadata (#1135 ) (aba0e24 )
forbid generating an access token without a session (#1504 ) (795e93d )
HTTP Hook - Add custom envconfig decoding for HTTP Hook Secrets (#1467 ) (5b24c4e )
ignore common Azure issuer for ID tokens (#1272 ) (4c50357 )
infer Mail in SAML assertion and allow deleting SSO user (#1132 ) (47ad9de )
initial fix for invite followed by signup. (#1262 ) (76c8eeb )
internalize implementation (#925 ) (1a52eb6 )
make dropping users_email_key backward compatible (#995 ) (aff2fe6 )
make error message in factor creation more obvious (#1374 ) (74af993 )
make phone data type alter backward compatible (#994 ) (551793e )
merge provider metadata on link account (#1552 ) (bd8b5c4 )
modify email duplicate lookup to use identities (#826 ) (a31545f )
new timeout writer implementation (#1584 ) (72614a1 )
no email password resets for users with no email identity (#793 ) (21c37ed )
pass transaction to invokeHook, fixing pool exhaustion (#1465 ) (b536d36 )
password sign-up no longer blocks the db connection (#1319 ) (84d4b75 )
PKCE magic link (#1016 ) (6fdad13 )
prefix release with v (#1424 ) (9d398cd )
properly return hook error (#1355 ) (890663f )
refactor for central password strength check (#1321 ) (5524653 )
refactor generate accesss token to take in request (#1531 ) (e4f2b59 )
refactor hook error handling (#1329 ) (72fdb16 )
refactor one-time tokens for performance (#1558 ) (d1cf8d9 )
refactor password changes and logout (#1162 ) (b079c35 )
refactor PKCE FlowState to reduce duplicate code (#1446 ) (b8d0337 )
refactor resource owner password grant (#1443 ) (e63ad6f )
reinstate upgrade whatsapp support on Twilio Programmable Messaging to support Content API (#1266 ) (00ee75c )
remove id_token flow with freeform provider (#927 ) (2646967 )
remove SafeRoundTripper and allow private-IP HTTP connections (#1152 ) (773e45e )
remove duplicate add_identities_email_column migrations, reorder others (#863 ) (ed08260 )
remove flow state expiry on Magic Links (PKCE) (#1179 ) (caa9393 )
remove legacy lookup in users for one_time_tokens (phase II) (#1569 ) (39ca026 )
remove non-SSO restriction for MFA (#1378 ) (9ca6970 )
remove opentracing (#1307 ) (93e5f82 )
remove saml beta warning (#1003 ) (794dab0 )
remove unused API NewAPIFromConfigFile (#909 ) (f91a450 )
rename gotrue to auth (#1340 ) (8430113 )
rename package to supabase from netlify (#947 ) (4f5c2f6 )
require different passwords on update (#1163 ) (154dd91 )
retry concurrent refresh token attempts (#1202 ) (d894012 )
return expires_at in addition to expires_in (#1183 ) (3cd4bd5 )
return bad request error when factor with duplicate friendly name is registered (#1375 ) (55febd2 )
return SMS ID when possible (#1145 ) (02cb927 )
revert "remove id_token flow with freeform provider" (#933 ) (4d98e30 )
saml: add not_after column to sessions table (not used) (#810 ) (8d7477a )
saml: add SAML ACS handler (disabled by default) (#779 ) (ae83dce )
saml: add SAML metadata endpoint (disabled by default) (#775 ) (41668b7 )
saml: add session expiration (not after timestamp) support (disabled by default) (#812 ) (6c6d3ad )
saml: add SSO authorization API (disabled by default) (#786 ) (fc6f58d )
saml: add SSO/SAML admin endpoints (disabled by default) (#771 ) (273b41f )
saml: add SSO/SAML migrations (#762 ) (437e683 )
saml: add X.509 Distinguished Name to generated certificate (#801 ) (8d85788 )
saml: remove unused features, small refactors (#846 ) (61c8eb8 )
saml: return JSON response on POST /sso with optional JSON response (#800 ) (dfe9143 )
send over user in SendSMS Hook instead of UserID (#1551 ) (d4d743c )
serialized access to session in refresh_token grant (#1190 ) (a8f1712 )
set updated_at on refresh_tokens when revoking family (#1167 ) (bebd27a )
simplify token reuse algorithm (#1072 ) (9ee3ab6 )
split validation and population of hook name (#1337 ) (c03ae09 )
spotify oauth (#1296 ) (cc07b4a )
strip user-agent from otel tracing (#1309 ) (d76f439 )
support for whatsapp as a channel for sending OTPs (#981 ) (d0d079f )
switch to github.com/supabase/mailme package (#1159 ) (dbb9cf7 ), closes #870
unlinking primary identity should update email (#1326 ) (bdc3300 )
update github.com/lestrrat-go/jwx/jwk to 1.2.25 (#926 ) (ff8ee5a )
update chi version (#1581 ) (c64ae3d )
update github.com/coreos/go-oidc/v3@v3.6.0 (#1115 ) (23c8b45 )
update github.com/rs/cors to v1.9.0 (#1198 ) (27d3a7f )
update oauth1.a flow (#1382 ) (4f39d2e )
update openapi spec with identity and is_anonymous fields (#1573 ) (86a79df )
update primary key for identities table (#1311 ) (d8ec801 )
update publish.yml checkout repository so there is access to Dockerfile (#1419 ) (7cce351 )
update README.md to trigger release (#1425 ) (91e0e24 )
update to Go 1.19 (#770 ) (e6525ab )
upgrade whatsapp support on Twilio Programmable Messaging (#1249 ) (c58febe )
use DO blocks around SQL statements in migrations (#1335 ) (061391a )
use otherMails with Azure (#1130 ) (fba1988 )
use template/text instead of strings.Replace for phone OTP messages (#1188 ) (5caacc1 )
use account linking algorithm (#829 ) (c709ed5 )
use dummy instance id to improve performance on refresh token queries (#1454 ) (656474e )
use OIDC ID token for Azure (#1269 ) (57e336e )
use unique message IDs for emails to prevent grouping (#986 ) (aaf2765 )
Bug Fixes
#1218 fixes existing migrations to allow namespaces!="auth" (#1279 ) (206fc09 )
createNewIdentity uses provided transaction (#776 ) (3f61950 )
account linking logic (#990 ) (17162c9 )
add email as verification type for email OTPs (#885 ) (8d21cbc )
add check for max password length (#1368 ) (41aac69 )
add checks for ownership for unenroll and verify (#835 ) (bdd9947 )
add cleanup statement for anonymous users (#1497 ) (cf2372a )
add db conn max idle time setting (#1555 ) (2caa7b4 )
add discord global_name to custom_claims (#1171 ) (3b1a5b9 )
add error handling for hook (#1339 ) (7ac7586 )
add guard check in case factor, session, or user are missing (#1099 ) (b4a3fec )
add http support for https hooks on localhost (#1484 ) (5c04104 )
add improved HTTP metrics (#768 ) (2f78644 )
add index on (session_id, revoked) in refresh_tokens (#765 ) (5ba3aca )
add index on identities.user_id (#781 ) (6c2c734 )
add mfa migrations (#722 ) (afdb223 )
add migration to backfill email identities (#823 ) (b54d60a )
add missing index on user_id under sessions (#763 ) (3332072 )
add profiler server (#1158 ) (58552d6 )
add redirectTo to email templates (#1276 ) (40aed62 )
add separate config for sms rate limits (#860 ) (1ff475c )
add swagger docs (#695 ) (8eefabb )
add test for all sms providers (#676 ) (de6cd79 )
add validation and proper decoding on send email hook (#1520 ) (e19e762 )
add validation to admin update user (#717 ) (497ce10 )
admin delete factor should be allowed to delete unverified factors (#854 ) (4c2bac3 )
admin user create & update (#929 ) (5526627 )
allow all URL forms in redirects (#711 ) (4ece9e3 )
allow any oauth providers to pass query params (#757 ) (ac2e7ae )
allow gotrue to work with multiple custom domains (#999 ) (91a82ed )
allow transactions to be committed while returning a custom error (#1310 ) (8565d26 )
backfill email identities for invited users (#914 ) (f7286dd )
bypass captcha for certain routes (#693 ) (70a6070 )
Change Dockerfile.dev target from netlify to Supabase (#973 ) (ee74d52 )
change email update flow to return both ? messages and # messages (#1129 ) (77afd28 )
check err before using user (#1154 ) (53e1b3a )
check for pkce prefix (#1291 ) (05c629b )
check freq on email change (#1090 ) (659ca66 )
check linking domain prefix (#1336 ) (9194ffc )
cleanup panics due to bad inactivity timeout code (#1471 ) (548edf8 )
confirm email on email change (#1084 ) (0624655 )
convert string -> *string for AAL and AMR (#785 ) (d887d18 )
correct pkce redirect generation (#1097 ) (bdf93b4 )
create identity for invited user (#895 ) (8ddf54b )
deprecate hooks (#1421 ) (effef1b )
disable allow unverified email sign ins if autoconfirm enabled (#1313 ) (9b93ac1 )
do call send sms hook when SMS autoconfirm is enabled (#1562 ) (bfe4d98 )
docs: remove bracket on file name for broken link (#1493 ) (96f7a68 )
don't encode query fragment (#1153 ) (e414cb3 )
don't update user metadata on subsequent signups (#825 ) (9e97a32 )
drop mfa flag (#831 ) (f0642c0 )
duplicate identity error on update user (#1141 ) (39ca89c )
enforce code challenge validity across endpoints (#1026 ) (be7c082 )
error should be an IsNotFoundError (#1432 ) (7f40047 )
expose provider under amr in access token (#1456 ) (e9f38e7 )
expose x-total-count and link (#991 ) (e6dac54 )
fetch new IDP metadata if stale (#833 ) (be3766d )
fill last_sign_in_at with a non-null value on backfilled email identities (#850 ) (ef1a51f )
fix flow state expiry check (#1088 ) (6000e70 )
format test otps (#1567 ) (434a59a )
garbled text in sms message when message contains unicode (#971 ) (55544e2 )
generate signup link should not error (#1514 ) (4fc3881 )
generateLink should create identity for invite & signup (#774 ) (0032b65 )
handle error properly for redirects (#887 ) (30c55e8 )
handle oauth email check separately (#1348 ) (757989c )
ignore exchangeCodeForSession when captcha is enabled (#1121 ) (4970bbc )
impose expiry on auth code instead of magic link (#1440 ) (35aeaf1 )
improve default settings used (4745451 )
improve logging structure (#1583 ) (c22fc15 )
improve MFA QR Code resilience so as to support providers like 1Password (#1455 ) (6522780 )
improve perf in account linking (#1394 ) (8eedb95 )
include /organizations in expected issuer exemption (#1275 ) (47cbe6e )
include email claim in identityData (#796 ) (930f5af )
include symbols in generated password (#1364 ) (f81a748 )
invalidate email, phone OTPs on password change (#1489 ) (960a4f9 )
IsDuplicatedEmail should filter out identities for the currentUser (#1092 ) (dd2b688 )
linkedin provider issue with missing avatar url (#847 ) (895fc2a )
linkedin_oidc provider error (#1534 ) (4f5e8e5 )
load user after sign-up to pull data from triggers (#712 ) (e553477 )
log clearer internal error messages for verify (#1292 ) (aafad5c )
log correct referer value (#1178 ) (a6950a0 )
log final writer error instead of handling (#1564 ) (170bd66 )
logout cookies not cleared (#830 ) (596dd70 )
lowercase emails (#714 ) (d65ba60 )
lowercase oauth emails for account linking (#1125 ) (df22915 )
maintain query params order (#1161 ) (c925065 )
make add_mfa_indexes re-runnable (#827 ) (00c21d8 )
make flow_state migrations idempotent, add index (#1086 ) (7ca755a )
make migration idempotent (#1079 ) (2be90c7 )
make migration idempotent (#923 ) (c792443 )
move all EmailActionTypes to mailer package (#1510 ) (765db08 )
move creation of flow state into function (#1470 ) (4392a08 )
nil pointer dereference in stale SAML metadata check (#977 ) (bb21c93 )
OIDC provider validation log message (#1380 ) (27e6b1f )
only apply rate limit if autoconfirm is false (#1184 ) (46932da )
only create or update the email / phone identity after it's been verified (#1403 ) (2d20729 )
only create or update the email / phone identity after it's been verified (again) (#1409 ) (bc6a5b8 )
pass through redirect query parameters (#1224 ) (577e320 )
patch secure email change (double confirm) response format. (#1241 ) (064e8a1 )
pkce bug with magiclink (#1074 ) (4b84129 )
pkce issues (#1083 ) (eb50ba1 )
populate password verification attempt hook (#1436 ) (f974bdb )
POST /verify should check pkce case (#1085 ) (7f42eaa )
potential panics on error (#1389 ) (5ad703b )
preserve backward compatibility with Twilio Existing API (#1260 ) (71fb156 )
prevent user email side-channel leak on verify (#1472 ) (311cde8 )
properly escape redirectTo URL for magic links (#750 ) (cc1d49d )
rate limiting not applied on phone OTP (#788 ) (6a129f3 )
refactor email sending functions (#1495 ) (285c290 )
refactor factor_test to centralize setup (#1473 ) (c86007e )
refactor mfa and aal update methods (#1503 ) (31a5854 )
refactor mfa challenge and tests (#1469 ) (6c76f21 )
refactor request params to use generics (#1464 ) (e1cdf5c )
releaserc (#680 ) (3f7f39e )
remove captcha on id_token grant (#1175 ) (910079c )
remove deprecated LogoutAllRefreshTokens (#1519 ) (35533ea )
remove duplicated index on refresh_tokens table (#1058 ) (1aa8447 )
remove foreign key constraint on refresh_tokens.parent (af00058 )
remove organizations from fly provider (#1267 ) (c79fc6e )
remove redundant queries to get session (#1204 ) (669ce97 )
rename from CustomSMSProvider to SendSMS (#1513 ) (c0bc37b )
rename metadata to data (#764 ) (70e354d )
resend email change (#1151 ) (ddad10f )
resend email change & phone change issues (#1100 ) (184fa38 )
Resend SMS when duplicate SMS sign ups are made (#1490 ) (73240a0 )
resolve nil pointer dereference issue (#813 ) (4d78d5f )
respect last_sign_in_at on secure password update (#1164 ) (963df37 )
restrict mfa enrollment to aal2 if verified factors are present (#1439 ) (7e10d45 )
return 404 instead of 500 in maybeLoadUserOrSession (#783 ) (92ddade )
return correct sms otp error (#1351 ) (5b06680 )
return error if session id does not exist (#1538 ) (91e9eca )
return error if user not found but identity exists (#1200 ) (1802ff3 )
return signup confirmation if signup is incomplete for magiclink / otp (#889 ) (8137dd8 )
return the latest flow state (#1076 ) (00c9a11 )
return unauthorized error for invalid jwt (#744 ) (85cff37 )
Revert "feat: no email password resets for users with no email identi& (#822 ) (1129482 )
Revert "fix: remove organizations from fly provider" (#1287 ) (84e16ed )
revert patch for linkedin_oidc provider error (#1535 ) (58ef4af )
revert refactor resource owner password grant (#1466 ) (fa21244 )
saml: access DB with context for SSO admin functions (#805 ) (ca9ad7a )
saml: always request persistent NameID in authn requests (#840 ) (3c2b56e )
saml: correct SSO domain, SAML attribute mapping update logic (#816 ) (9dbdd61 )
saml: not specifying domains should not delete all domains (#851 ) (c1ad911 )
saml: persist attribute mappings on provider create and update (#802 ) (af7c8ba )
saml: saml user accounts not being set as is_sso_user (#841 ) (e290983 )
saml: use SessionNotOnOrAfter from the authn. statement instead of conditions (#838 ) (35acc4c )
sanitizeUser leaks user role (#1366 ) (8ce9d3f )
set emailChange to email (#920 ) (c23b6ce )
set the otp if it's not a test otp (#1223 ) (3afc8a9 )
show proper error message on textlocal (#1338 ) (44e2466 )
skip captcha on POST /verify (#795 ) (eef1bb7 )
skip rate limit if header not present (#706 ) (8fb0c1e )
sms verify should update is_anonymous field (#1580 ) (e5f98cb )
support email verification type on token hash verification (#1177 ) (ffa5efa )
support message IDs for Twilio Whatsapp (#1203 ) (77e85c8 )
switch to aws roles (#893 ) (76c8710 )
take into account test otp for twilio verify (#1255 ) (18b4291 )
test otp with twilio verify (#1259 ) (ab2aba6 )
unenroll should remove totp amr claim (#758 ) (c7a62de )
unlink identity bugs (#1475 ) (73e8d87 )
unmarshal is_private_email correctly (#1402 ) (47df151 )
update .yml to mfa (#731 ) (e034ca0 )
update dependencies (1/2) (#1304 ) (accccee )
update email, phone identities on change (#824 ) (390e34d )
update file name so migration to Drop IP Address is applied (#1447 ) (f29e89d )
update from oauth_pkce to pkce (#1017 ) (63bc007 )
update github.com/crewjam/saml from 0.4.8 to 0.4.9 (#839 ) (7a10a05 )
update gobuffalo to v5.3.4 (#814 ) (aa1ff23 )
update linkedin issuer url (#1536 ) (10d6d8b )
update password should logout all other sessions (#806 ) (4b4ca39 )
update phone if autoconfirm is enabled (#1431 ) (95db770 )
update settings & route for SAML (#1009 ) (f405615 )
update soft deletion (#894 ) (6581728 )
update suggested Go version for contributors to 1.21 (#1331 ) (9feeec4 )
upgrade pop version (#1069 ) (969691f )
use pattern for semver docker image tags (#1411 ) (14a3aeb )
use api_external_url domain as localname (#1575 ) (ed2b490 )
use clear hCaptcha error messages (#789 ) (2906976 )
use configured redirect URL for external providers (#1114 ) (42bb1e0 )
use email change email in identity (#1429 ) (4d3b9b8 )
use linkedin oidc endpoint (#1254 ) (6d5c8eb )
use proper index name in 20221215195500_modify_users_email_unique_index (9eda0ab )
use started transaction, not a new one (#1196 ) (0b5b656 )
Reverts
"fix: only create or update the email / phone identity after i& (#1407 ) (ff86849 )
You can’t perform that action at this time.